Boston Scientific - One Network B...

Boston Scientific - One Network Box, Two Weeks Without Shipping, and Nothing Encrypted

AI
Tech Talks With Kinsoft by Steven Kinnas
Sep 24, 2026
22:22

Episode notes

A catch-up episode, recorded after the fact. The investigation had concluded and been published by 23 September (AEST).

US medical device maker Boston Scientific lost roughly two weeks of manufacturing and shipping to a cyber intrusion in which, according to CrowdStrike, nothing was encrypted and no data was taken.

Timeline (US time). 25 August: system availability issues traced to an unauthorised third party; containment begins and CrowdStrike is engaged. 26 August: voluntary SEC disclosure. 30 August: no further unauthorised activity since 25 August; cloud systems unaffected. 3–5 September: shipping and most manufacturing resume. 7–8 September: material-incident SEC filing; the company says it is unlikely to meet Q3 and full-year guidance, with a new outlook due 28 October. 9 September: manufacturing, fulfilment and shipping fully restored. 18 September: investigation concludes. By 23 September (AEST): CrowdStrike summary published.

What CrowdStrike found. Entry via "an external-facing network management device" — vendor, model and method not disclosed; the device has been decommissioned. No evidence of encryption; no activity in Microsoft 365 or email; no interactive access to HR, manufacturing, SCADA or product development systems; no logins to SAP, Salesforce or cloud apps; no evidence that data, including patient or customer data, was accessed or taken. Implanted devices unaffected. No group has credibly claimed it and no CVE has been linked; attributions to ShinyHunters and a pro-Russian group are unsupported. Not yet explained: how an intrusion without encryption caused a two-week outage.

Lessons. Inventory and harden internet-facing management devices, with management interfaces off the internet and MFA on. Map which systems the business cannot run without. Logging is what lets you state that no data was taken — and in Australia, it decides whether you have a notifiable breach. A staged, frequent, evidence-based disclosure is a good model for ASX continuous disclosure too.

Visit www.kinsoft.com.au to talk through your security and IT needs.

Sources: Boston Scientific SEC filings (26 August and 8 September 2026); Boston Scientific incident updates; CrowdStrike investigation summary; TechCrunch; SecurityWeek; HIPAA Journal; Quartz; MedTech Dive; 24x7 Magazine.